Allow elevated access on getDomainById and verify-dns endpoints

FixSecurityService
Shipped
April 29, 2026 at 1:35 AM UTC
Author
Kamo
Commit
fe14c5f

Top-level org owners and system members were getting 403 on getDomainById and verify-dns because those endpoints checked isUserMemberOfOrg directly. Adds hasElevatedCrossOrgAccess helper and applies it alongside the member check.

All changes

Like what you see shipping?

Every one of these updates lands in your workspace automatically. Start free and watch it grow week after week.

Start Free ForeverView Pricing